Lada Consulting

Your AI Policy, Staff Guide, and Procedures

AI

Your AI Policy, Staff Guide, and Procedures

Who, When, Why, and How to Get Started

D
Dr. Cathy Lada, D.Sc., CAE, AAiP
9 min read
Last updated: June 15, 2026

Who, When, Why, and How to Get Started

If you've ever sat through a meeting where someone asked, "Wait, are we allowed to use ChatGPT for that?" and nobody had a clean answer, this post is for you.

Most associations need AI governance discipline. Staff are using AI tools. Leadership knows it. Nobody has written down what's okay and what isn't. So everyone gets cautious, or careless, or both.

The fix is to create a policy and a staff guide to its use, along with standard operating procedures (SOPs). They do different jobs.

What Each Document Does

AI Policy establishes what your association believes and requires. A staff guide makes the policy operable in the moment. The policy is the durable document. It's where you've worked through governance, ethical use, data protection, and accountability. The staff guide is the working companion. It's the version your team will actually consult before pasting member data into a tool, before running a meeting transcription, before approving a vendor's new AI feature. Together they do what neither does alone.

AI procedures and processes (SOPs) should also be captured in a separate document.

Why Now

A few realities to sit with:

  • Staff are already using AI tools. The question isn't whether AI is in your association; it's whether your association has rules for it.
  • Shadow AI use is a real risk. Without guidelines, people either avoid AI entirely (out of caution) or paste member data into public tools (out of convenience).
  • Disclosure standards are tightening. Several professional associations now require AI disclosure in peer-reviewed content. The EU AI Act and various US state laws are starting to mandate disclosure for certain AI-generated content.
  • It's easier to build the habit of clarity now than to retrofit it later.

So the timing is less about "AI is coming" and more about "AI is here, and you need a position on it."

Who Should Be Involved

This is not a one-person job. It's also not a thirty-person job. A small, cross-functional working group gets you the best result.

Required at the Table

  • Executive Director or CEO. Owns the strategic framing and makes the final call on contested decisions.
  • IT or Information Security Lead. Knows what data you have, where it lives, and what enterprise tools are available.
  • HR. Owns the staff-conduct and training pieces.
  • Legal counsel. Reviews for compliance with state, federal, and industry-specific requirements. (In highly regulated industries like healthcare, insurance, and finance, this is non-negotiable.)
  • Marketing and Communications. Often the heaviest AI users; needs to weigh in on disclosure norms.
  • Operations. Translates the policy into day-to-day workflow.

Strongly Recommended

  • Include a staff representative who isn't a department head. The people closest to the keyboard see things leadership misses.
  • The membership or education team if your association holds significant member-generated content (forums, certification materials, body of knowledge).

Board Touchpoints

Two formal moments:

  • Pre-pilot briefing. A 10-minute update framed as risk management, not a tech project. Cover why now, what staff can and can't do, what you're protecting, and when the board will see the full AI policy.
  • Policy review and approval. The board should sign off, especially on decisions about training AI on association data, member content, or intellectual capital.

When to Start (and What Order)

The sequence matters more than the speed.

The Five-Step Sequence

  • Identify policy ownership. Who has authority to approve tools, update the policy, and review violations? Common options: Executive Director, CIO, Chief Marketing or Digital Officer, or a cross-functional governance committee.
  • Write the policy and the staff guide to its use in parallel, not sequence. Drafting the staff guide often surfaces gaps in the policy before you finalize it.
  • Send the policy to legal and IT. State laws, federal regulations, and contractual obligations vary. Don't skip this.
  • Train staff before turning them loose. Policies are only effective when employees understand them. The staff guide provides valuable in-the-moment guidance.
  • Set a review cycle. Most associations review every six months or annually, plus whenever significant regulatory or technology changes occur.

What to Include in Your AI Policy

Use this as a checklist, not a table of contents you have to follow word-for-word.

Core sections

  • Purpose, scope, and goals. Why this policy exists, who it applies to, and what it's meant to achieve.
  • Governance and oversight. Who owns the policy; review cycle; enforcement authority.
  • Ethical AI framework. Transparency, fairness and bias, decision authority, human accountability. These are belief statements; they belong in the policy.
  • Data privacy and security: the rules. Prohibited data categories; the requirement to anonymize; the requirement for security review; approval criteria; consequences of violation.
  • Permission requirements for member and speaker content. That permission is required; what content is covered.
  • Copyright and intellectual property. Restrictions on AI-generated brand assets; non-infringement requirement.
  • Human oversight requirements. Final accountability rests with the human author.
  • Training and awareness expectations. That training is required; cadence; who must complete it.
  • AI in meetings and recordings. Rules for board, committee, webinar, and internal use; consent requirements.
  • AI use in specific functions. Function-level guardrails for marketing, research, HR, and so on.
  • Member data and community content protections. What's protected, what's prohibited.
  • Protection of association intellectual capital. Bodies of knowledge, certification materials, competency frameworks. Board approval required for training models on these assets.
  • Vendor and partner AI use. Disclosure expectations; contract requirements; monitoring expectations; incident response obligations.
  • Approved AI tools list and request process: the authority. Who approves, what criteria apply.
  • AI agents and automation. What may not be delegated to autonomous agents; what requires leadership approval.
  • Incident reporting requirement. That incidents must be reported; to whom; within what window leadership must respond.
  • Continuous improvement and policy updates. Review cadence; who approves changes; how staff input is gathered.

A quick disclaimer: I'm not a lawyer. The list above may be sufficient for many associations, but with differing state and federal laws, you'll still want to check whether there are specific restrictions required or suggested for your industry.

Procedures Documents

These are the workflow pieces. They reference the policy; they don't restate it. Create standard operating procedures (SOPs) to help staff quickly and safely do the work. Here are some suggested areas to cover:

  • Data handling steps. How to anonymize a member record before pasting into a tool; the checklist of data types to scrub.
  • Tool security review workflow. The form, the reviewer, the turnaround time.
  • Permission collection process. Templates for speaker agreement language; where signed permissions are stored; who maintains the log.
  • AI disclosure language. Sample disclosure statements for reports, white papers, and educational materials.
  • Bias and accuracy review checklist. The specific steps a staff member walks through before publishing AI-assisted content.
  • Pre-publication human review checklist. What to verify, what to edit, what to document.
  • Training curriculum and tracking. What's in the training; who delivers it; how and where completion is recorded.
  • Meeting and recording workflows. Consent script for participants; how to label AI-summarized minutes; transcription tool setup.
  • Department-specific use cases and prompt libraries. The actual prompts, examples, and templates by function.
  • Member data handling procedures. Step-by-step for the most common scenarios.
  • IC protection procedures. How to flag a request that touches certification materials, bodies of knowledge, or competency frameworks; who it routes to.
  • Vendor review checklist and contract clause library. What to ask vendors; what language to include in contracts.
  • Current approved tools list. The live list, updated as tools are added and removed.
  • New tool request form and workflow. How to ask, what to include, who decides.
  • AI agent deployment request workflow. What to submit before deploying an automation that triggers workflows.
  • Incident report form and escalation path. The form itself; the contact list; the 5-business-day clock.
  • Feedback collection mechanism. Where staff submit concerns, emerging risks, and ideas for new safe AI uses.

What to Include in Your Staff Guide

The one-to-three page staff version answers four questions, fast:

  • What can AI be used for? Approved tools, common acceptable tasks.
  • What data must never be uploaded? Member data, financial data, HR information, confidential documents, legal matters, passwords, proprietary strategy, personally identifiable information.
  • When does AI use need to be disclosed? Research reports, white papers, educational materials, public policy statements. Not required for routine marketing copy or internal drafts.
  • When does staff need to ask for approval? New tools, new use cases, anything involving member or speaker content.

If a new hire only reads one policy about AI on day one, this is the document.

A Few Pitfalls to Avoid

  • Drafting the policy in a vacuum. If only IT writes it, it'll be too restrictive. If only marketing writes it, it'll skip the security pieces. Use a cross-functional team.
  • Over-engineering before launch. You will revise this in six months. Publish a good v1, not a perfect v3.
  • Forgetting the staff guide The policy that lives on a shared drive is not the policy that governs behavior in the moment. The staff guide is.
  • Skipping board alignment early. If the board is going to be the gatekeeper on AI training data and member content licensing later, they should see the framework now.

Your Next Step

You can't edit a blank screen. So start with the smallest possible draft, get the right people in the room, and iterate from there. We've created a sample AI staff use guide - download it today and customize it to your association. This sample guide and the AI policy guidance above were developed based on publicly available research and current industry practice. They are intended as a starting point, not a finished compliance document. Before adopting or distributing this guide or policy, review it with qualified legal counsel familiar with your organization's jurisdiction, sector, and specific risk profile. AI tools, regulations, and organizational contexts vary enough that no single template will be the right fit without some adaptation. Use this as a foundation for your own thinking, not a substitute for it.

Need Help?

Book a meeting to discuss your needs with me!

Explore Topics

D

Written by

Dr. Cathy Lada, D.Sc., CAE, AAiP

Content creator and writer sharing insights and stories.